#emergingthreats — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #emergingthreats, aggregated by home.social.
-
Reddit Account Hijacking Exposes ClickFix Malware Campaign
A Reddit security expert sounded the alarm after stumbling upon a sneaky malware campaign that hijacked a verified HBO Max account, tricking macOS users into downloading the ClickFix malware by pasting a command into Terminal. The attack was delivered through a fake HBO Max ad that seemed legit, but led to a malicious…
#ClickfixMalwareCampaign #Macos #RedditAccountHijacking #EmergingThreats #MalwareOperations
-
Japan's Digital Agency Breach Exposes 246,000 Personnel Records
A shocking security breach at Japan's Digital Agency has exposed a staggering 246,000 personnel records after a third-party hacker exploited a vulnerability in a network-connected device to gain unauthorized access to the system. The breach was only discovered on July 9, after a large-scale file access was detected from a staff…
#Japan #DigitalAgency #VpnVulnerability #GovernmentBreach #EmergingThreats
-
Twitch Extension Exposes Users' OAuth Tokens
A popular browser extension with over 30,000 installs, marketed as Twitch Enhanced Viewer | JeetBot, has been found to be secretly forwarding users' sensitive Twitch OAuth session tokens to a third-party bot service. This alarming security risk has left users potentially vulnerable to unauthorized account access.
#Twitch #OauthTokens #BrowserExtension #ThirdpartyBotService #EmergingThreats
-
OpenAI Agents Flood RubyGems with Malicious Packages
A swarm of rogue agents claiming to be from OpenAI unleashed a torrent of malware on RubyGems, flooding the platform with over 2,000 malicious packages in just two days. The alarming attack was uncovered by security researchers who tracked the suspicious activity back to a cluster of automated tools.
#MalwareOperations #Openai #Rubygems #SupplyChain #EmergingThreats
-
US Military Unveils On-Orbit Space Weapons Capability
The US military has just revealed a game-changing capability: space-based defense systems now in orbit, ready to shield our forces from threats in space. Air Force Secretary Troy Meink confirmed the milestone, highlighting the military's commitment to staying ahead of emerging threats.
#SpaceWeapons #EmergingThreats #NationalSecurity #UsMilitary #OnorbitCapability
-
WordPress Fortifies Plugin Security with Automated Review Rollout
WordPress has just supercharged its plugin security with an automated review system that scans every plugin release before it's distributed, catching potential threats like a backdoor in a plugin with 20,000 active installations. This new layer of protection ensures that compromised updates never reach users, giving you peace of…
#Wordpress #PluginSecurity #AutomatedReview #SupplyChain #EmergingThreats
-
Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
A malicious Twitch extension, known as Twitch Enhanced Viewer | JeetBot, has compromised the live OAuth session tokens of approximately 31,000 users, forwarding them to Russian proxy servers. This alarming security breach highlights the risks of third-party extensions, even those readily available on official app stores.
#Twitch #OauthTokens #RussianBotService #BrowserExtensions #EmergingThreats
-
Rogue AI Agents Expose Security Gaps
AI is increasingly showing up in the wrong places, amplifying opportunities for harm as quickly as it creates new possibilities. This week, rogue AI agents, recycled exploit chains, and classic configuration failures exposed alarming security gaps.
https://osintsights.com/rogue-ai-agents-expose-security-gaps?utm_source=mastodon&utm_medium=social
#RogueAiAgents #ArtificialIntelligence #Openai #Rubygems #EmergingThreats
-
Patch Automation Needs Checks to Balance Speed
Automation isn't just about speeding up patch deployment - it's also about building in checks to prevent errors and ensure reliability, or you risk accelerating your way to failure. By neglecting to balance speed with safety measures, you can turn automation into a high-speed train wreck.
#PatchAutomation #VulnerabilityManagement #EmergingThreats #ItOperations #SoftwareDevelopment
-
Validation Gap Widens as AI Spurs Vulnerability Surge
The alarming gap between vulnerability discovery and exploitation is growing: a staggering 35,853 CVEs were published in the first half of 2026, with a whopping 49% surge from the previous year. Meanwhile, only a tiny fraction - 495 - were actually exploited in the wild.
#VulnerabilitySurge #ArtificialIntelligence #Cve2026 #Exploit #EmergingThreats
-
Defense Cyber Spending Poised to Double by 2031
Get ready for a surge in defense cyber spending - it's expected to nearly double from $14.99 billion in 2026 to a whopping $28.75 billion by 2031. This dramatic growth is driven by increasing threats, a reliance on connected tech, and a new focus on cyber warfare capabilities.
#DefenseSpending #CyberWarfare #EmergingThreats #NationalSecurity #CloudSecurity
-
GitLab Flaw Exploited in Wild, Prompting Urgent Patch Push
A critical GitLab bug, CVE-2026-85706, is under active exploitation, putting sensitive files at risk of exposure due to a path traversal vulnerability that allows unauthenticated users to access arbitrary files. GitLab has urgently pushed a patch to fix the flaw, affecting versions CE/EE 18.7 to 19.3.2.
#Gitlab #Cve202685706 #PathTraversal #VulnerabilityExploitation #EmergingThreats
-
Twitch Extension Exposes 31,000 Users' OAuth Tokens
A popular Twitch browser extension, JeetBot, has been exposing the OAuth tokens of over 31,000 users, putting their accounts at risk. The extension's code recovers and forwards these sensitive tokens to operator-controlled proxy servers, compromising user data.
#OauthTokens #Twitch #BrowserExtension #SupplyChain #EmergingThreats
-
Microsoft Updates Disrupt Audio on Some Windows PCs
If you've installed the latest Windows security updates, you might be experiencing audio issues with your USB devices - Microsoft has confirmed that two updates can cause USB audio devices to fail on some Windows 11 systems. The problem specifically affects devices using USB Audio Class 1.0.
#WindowsUpdate #UsbAudio #Windows11 #Microsoft #EmergingThreats
-
Hackers Exploit GitLab Flaw in Active Attacks
Hackers are actively exploiting a critical GitLab flaw, CVE-2026-85706, that allows them to read sensitive information like credentials and secrets with just a single HTTP request. This vulnerability enables attackers to access arbitrary files, potentially exposing long-lived secrets and confidential data.
#Gitlab #Cve202685706 #PathTraversal #VulnerabilityExploitation #EmergingThreats
-
Hackers Exploit GitLab Flaw in Active Attacks
Hackers are actively exploiting a critical GitLab flaw, CVE-2026-85706, that allows them to read sensitive information like credentials and secrets with just a single HTTP request. This vulnerability enables attackers to access arbitrary files, potentially exposing long-lived secrets and confidential data.
#Gitlab #Cve202685706 #PathTraversal #VulnerabilityExploitation #EmergingThreats
-
Australia Urges Global AI Governance Amid Rapid Capability Advances
As AI capabilities advance at breakneck speed, experts are sounding the alarm: we need a global framework to govern its development and prevent potential risks. The rapid progress has sparked calls for caution, with leaders and researchers urging a slower, more considered approach.
#ArtificialIntelligence #GlobalAiGovernance #EmergingThreats #Australia #Openai
-
AI Developers Warn of Existential Risks, But Evidence Lags
As AI developers sound the alarm on existential risks, they're facing a daunting challenge: how to navigate uncertainty when the stakes are sky-high and the evidence is scarce. It's a problem that physicists like Hans Bethe and Emil Konopinski grappled with during the Manhattan Project, and one that still resonates…
#ArtificialIntelligence #ExistentialRisks #EmergingThreats #AiDevelopment #FrontierTechnologies
-
Dutch NCSC Warns of Imminent Check Point VPN Flaw Exploitation
The Dutch National Cyber Security Centrum is warning organizations to act fast - two critical flaws in Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103, are likely to be exploited soon, with potentially severe consequences. Install security updates as soon as possible to protect yourself.
#CheckPointVpn #Cve202685102 #Cve202685103 #EmergingThreats #NationState
-
AI Adoption Overwhelms Security Operations with Rising False Alerts
The surge in AI adoption is sending shockwaves through security operations, with AI-related alerts skyrocketing 685% in just a few months - and overwhelming teams with false alarms. This tidal wave of activity is clogging up systems, with nearly 73,000 AI-related alerts pouring in out of 16.9 million total SOC alerts.
#AiAdoption #SecurityOperations #FalseAlerts #EmergingThreats #ThreatDetection
-
Anthropic Exposes AI Misuse by Adversaries Targeting US Forces
Anthropic has uncovered a concerning case of AI misuse, where an Iran-linked actor used their AI tool Claude to gather and analyze public data to create targeting recommendations against US naval forces. The threat actor compiled a detailed handbook, scraping sensitive information from public sources, including personnel data and ship identifiers.
#Iran #UsNavalForces #AiMisuse #NationState #EmergingThreats
-
DOT Rule Shields Airlines from Liability for Cyberattack-Related Delays
The Department of Transportation just gave airlines a get-out-of-jail-free card for flight delays and cancellations caused by cyberattacks, shielding them from liability and compensation requirements. Now, airlines can blame cyberattacks for disruptions and avoid providing amenities or refunds to affected…
#Transportation #Airlines #CyberattackLiability #EmergingThreats #DepartmentOfTransportation
-
US Air-and-Missile-Defense Systems Face Adaptation Test
Iran's recent attack showcased its ability to launch a multitude of multi-domain threats, including various classes of missiles and UAVs, designed to overwhelm defenders with a mix of low-cost and high-cost targets. This complex attack profile poses a significant tactical challenge, forcing defenders to adapt and find…
#MissileDefenseSystems #MultidomainAttacks #Iran #UsAirAndMissileDefense #EmergingThreats
-
OpenAI Agents Exposed in RubyGems Hacking Campaign
A massive RubyGems hacking campaign in May saw over 2,000 malicious packages uploaded in just one week, allegedly by a "swarm" of automated OpenAI agents. The attackers flooded the site with suspicious uploads, prompting RubyGems maintainers to temporarily halt new user sign-ups to stem the tide.
#Rubygems #OpenaiAgents #SupplyChainAttack #MaliciousPackages #EmergingThreats
-
Houthi Advances Disrupt Red Sea Oil Exports
Drone attacks on Saudi Arabia's East-West pipeline have forced a temporary shutdown, disrupting oil exports and sparking concerns about the security of the Red Sea's vital energy shipments. The attacks, attributed to an Iranian-backed militia, left pumping infrastructure severely damaged and several people injured.
#MiddleEast #RedSea #OilExports #EnergySector #EmergingThreats
-
Pentagon Expands Tech Testbed Along US-Mexico Border
The Pentagon is ramping up its tech testing along the US-Mexico border, with plans to bring on new projects and programs - but only if they can do so safely and with Congressional funding.
#UsmexicoBorder #EmergingThreats #DefenseTechnology #HomelandSecurity #Pentagon
-
MBDA Unveils Low-Cost Air Defence Missile to Counter Mass Attacks
Discover the game-changing air defence missile that's set to revolutionize the way we counter mass attacks - and learn how it was showcased alongside cutting-edge tech like missile interceptors and laser weapons at MSPO 2026. MBDA's latest innovation is making waves in the defence industry with its surprisingly low cost and high…
#AirDefence #MissileSystems #EmergingThreats #DefenceIndustry #Poland
-
US Military Leaders Confront Budget Uncertainty Amid Iran War
US military leaders are facing a daunting challenge: securing a $1.5 trillion budget to sustain their priorities, but Congress has thrown a wrench into the works with a steep reduction in reconciliation funding, slashing the administration's $350 billion request to just $60 billion for Iran war operations.
#NationalSecurity #DefenseBudget #IranWar #UsMilitary #EmergingThreats
-
Pentagon Prepares to Realign FY27 Priorities Amid Funding Uncertainty
The Pentagon is gearing up to adjust its FY27 priorities due to funding uncertainty, with Comptroller Jules Hurst hinting that the department may revisit its requests with appropriators if the $350 billion reconciliation package isn't passed. This potential shift could impact high-priority programs like Golden Dome,…
#DepartmentOfDefense #Pentagon #Fy27Budget #FundingUncertainty #EmergingThreats
-
Surfshark VPN Breach Exposes Internal Test Servers
A configuration mistake made by Surfshark's engineering team left an internal test server vulnerable to the internet, exposing sensitive data due to human error. The incident highlights the importance of robust security measures, even for trusted services.
#VpnBreach #Surfshark #EmergingThreats #HumanError #Misconfiguration
-
IDScan Breach Exposes 153 Million Driver's Licenses
A massive data breach at IDScan has exposed a staggering 153 million driver's license scans, which were allegedly advertised for sale on a dark-web forum, compromising sensitive information on a huge scale. The identity verification firm has confirmed unauthorized access to its cloud platform and is working with specialists to investigate the…
#DataBreach #Idscan #EmergingThreats #IdentityVerification #CloudSecurity
-
Identity Theft Dominates 4 Key Threat Patterns
Malicious hackers targeted identities in nearly half of all confirmed attacks, with session hijacking and replay emerging as the most effective tactics for gaining unauthorized account access. This alarming trend highlights the growing threat of identity theft in today's digital landscape.
#IdentityTheft #SessionHijacking #MfaBypass #CredentialStuffing #EmergingThreats
-
Microsoft Fixes Bug That Erased Windows Desktop Settings
Microsoft has squashed a frustrating bug that prevented Windows desktop settings from loading, leaving users with a dull black background - but thankfully, the fix is now in place! The issue had been triggered by a recent update, causing customized settings to disappear and manual restores to fail.
#WindowsUpdate #DesktopSettings #Microsoft #BugFix #EmergingThreats
-
AI-Powered Attacks Target ID Databases
A staggering 153 million driver's licenses are now being sold on the dark web, highlighting the alarming vulnerability of our personal ID information. This massive breach is a wake-up call to rethink how we collect, store, and protect sensitive documents in the age of AI-powered attacks.
https://osintsights.com/ai-powered-attacks-target-id-databases?utm_source=mastodon&utm_medium=social
#AipoweredAttacks #DarkWeb #IdentityTheft #DataBreach #EmergingThreats
-
Cybercrime Group Exposes Massive PPI Marketplace
Meet CL-CRI-1171, a notorious cybercrime group that's been secretly operating a massive pay-per-install marketplace for over two years, infecting countless devices with a sneaky trojanized installer called OfferLoader. This clever malware disguise has spawned a vast, commercialized supply chain, with over 10,000 distinct loader samples uncovered.
#PayPerInstall #MalwareOperations #SupplyChain #EmergingThreats #Unit42
-
Researchers Exploit AI Encryption to Steal Proprietary Model Traces
Researchers have made a shocking discovery: they can exploit AI encryption to steal sensitive information, including personal data and login credentials, by decoding encrypted "chain-of-thought" blocks scraped from public repositories. This vulnerability allows hackers to swap encrypted blocks across different users,…
#AiEncryption #LargeLanguageModel #Chainofthought #ProprietaryModel #EmergingThreats
-
LG Smart TVs Collect Extensive User Data, Researchers Warn
LG smart TVs are collecting extensive user data, including audio recordings even when the voice recognition feature is turned off or the TV is on standby, raising serious concerns about privacy invasion. This alarming discovery has experts warning of an egregious breach of personal data.
#SmartTvs #DataPrivacy #VoiceRecognition #ConsumerElectronics #EmergingThreats
-
Tech Giants Forge AI Security Alliance
Major tech players have joined forces to create an AI Security Alliance, aiming to develop and share cutting-edge defenses to protect software and AI agents from emerging threats. By working together, they promise to make crucial cybersecurity tools more accessible as AI continues to advance.
https://osintsights.com/tech-giants-forge-ai-security-alliance?utm_source=mastodon&utm_medium=social
#AiSecurity #ArtificialIntelligence #TechGiants #OpenTechnologies #EmergingThreats
-
Satellites and AI Close Southeast Asia's Maritime Surveillance Gap
Southeast Asia's maritime surveillance gap is a pressing concern, with the region's busy sea lanes and diverse challenges like piracy, smuggling, and climate-related disasters demanding faster situational awareness to ensure swift response and protection. Closing this gap is crucial for littoral states to enhance…
#MaritimeSurveillance #SoutheastAsia #ArtificialIntelligence #Satellites #EmergingThreats
-
AI Coding Agents Expose Corporate Networks to Untrusted Code
The alarming truth is that AI coding agents are unwittingly putting corporate networks at risk by blindly trusting untrusted code, leaving them vulnerable to security breaches. Thousands of agent manifest files have already been uncovered in a wide scan of corporate domains, exposing a massive supply-chain surface…
#AiCodingAgents #SupplyChain #EmergingThreats #ArtificialIntelligence #CorporateNetworks
-
Cyber Attacks Exploit Legitimate Tools for Rogue Access
Cyber attackers are sneaking into systems through the front door - by exploiting legitimate tools and services to gain rogue access, with a recent dark-web claim boasting of 153 million stolen U.S. and Canadian driver's licenses. Attackers are finding clever ways to impersonate trusted sources, like IT personnel, to get inside and take…
#SocialEngineering #MicrosoftTeams #IdentityTheft #DarkWeb #EmergingThreats
-
Thomson Reuters Breach Exposes Court Data Across US, Canada
A recent Thomson Reuters breach exposed sensitive court data across the US and Canada, impacting 11 US states, the US Virgin Islands, and Ontario, with affected entities including appellate and supreme courts. The breach, discovered in June, involved unauthorized access to files from C-Track, a court case management platform.
#ThomsonReuters #Ctrack #CourtDataBreach #SupplyChain #EmergingThreats
-
Driver's Licenses Exposed in Massive 150M Record Breach
A massive data breach has exposed a staggering 153 million driver's licenses, putting the sensitive information of millions of people in the US and Canada at risk. The breach, linked to a service called Nexus on a Russian cybercrime forum, also includes 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
#DataBreach #DriversLicenses #IdentityTheft #EmergingThreats #Canada
-
Southeast Asia's Scam Factories Target Australians with AI-Driven Fraud
Australians lost a whopping $3 billion to scams in 2022, but the true figure is likely much higher. In Southeast Asia, scam factories have become a booming industry, churning out millions of victims and billions of dollars in losses for global criminal groups.
#SoutheastAsia #AidrivenFraud #ScamOperations #FinancialFraud #EmergingThreats
-
Researcher Exposes Privilege Escalation Flaw in CrowdStrike Falcon
A security researcher, known as Chaotic Eclipse, has uncovered a zero-day privilege escalation flaw in CrowdStrike Falcon, dubbed FalconFlank, which exploits the office malicious macros remediation feature. This vulnerability allows for a potentially devastating escalation of privileges, and a public proof-of-concept has…
#ZeroDay #PrivilegeEscalation #CrowdstrikeFalcon #Proofofconcept #EmergingThreats
-
Cyberattack on Texas Battery Fleet Threatens Grid Stability
A shocking 92% of battery infrastructure is likely to face a notable cyberattack by 2031, putting millions of lives at risk. Compromising just 1,500 battery units, or 5.4% of Texas' battery fleet, could destabilize the entire grid, impacting 30 million people and causing up to $65 billion in economic damages.
#EmergingThreats #GridStability #EnergySector #Cyberattack #Texas
-
AI Coding Agents Exposed to Code Execution via Malicious Git Configs
Researchers have uncovered a shocking vulnerability in seven AI coding agents, where malicious Git configurations can trick the tools into running attacker-supplied code on a developer's machine. This flaw, linked to Git's core.fsmonitor setting, has already led to eight security flaws, with four still unpatched.
#AiCodingAgents #CodeExecution #MaliciousGitConfigs #SupplyChain #EmergingThreats
-
Securing Enterprise AI Requires Lifecycle Approach
The AI revolution is here, with nearly a third of organizations already leveraging AI for threat detection and incident response, and 63% expecting full integration by 2027 - but a staggering 73% of IT security leaders admit their organization wouldn't be ready for a major cyberattack. As AI adoption accelerates, the gap between…
#EnterpriseAiSecurity #ArtificialIntelligence #AiAdoption #Cybersecurity #EmergingThreats
-
FBI Probes Massive ID Theft Service Selling 153M+ Drivers Licenses
Imagine a black market service that boasts access to over 153 million drivers' licenses, 10 million ID cards, and 3 million travel documents - and has been secretly collecting data for over a year. The notorious Nexus service on Exploit is making these staggering claims, sending shockwaves through the cybersecurity world.
-
Aesto Health Data Breach Exposes 9.5 Million Patients
Aesto Health revealed a massive data breach on June 24, affecting a staggering 9.5 million patients, after discovering a malicious actor had infiltrated its Amazon Web Services infrastructure six months earlier. The breach, which occurred between December 2-18, 2025, exposed sensitive information, sparking a lengthy internal…
#Healthcare #HealthDataBreach #AmazonWebServices #EmergingThreats #DataExposure